This extension shows critical risk indicators. It requests highly sensitive permissions combined with suspicious code patterns. Proceed with extreme caution.
Based on 13 permissions including high-risk ones, 36 code findings, 4 dangerous combinations.
Extension has cookie access and sends data to external servers — potential session token theft.
Extension tracks open tabs and communicates with external servers — potential browsing surveillance.
Extension intercepts network traffic and sends data externally — potential man-in-the-middle behavior.
Extension has access to all sites and captures keyboard input — behavior consistent with a keylogger.
This extension does not define a Content Security Policy. A CSP helps prevent XSS and code injection attacks.
Web-accessible resources use <all_urls> or wildcard patterns, exposing resources to every website.
JavaScript files are exposed as web-accessible resources. Matched websites can load and interact with extension scripts.
58 indicators of compromise found